Vulnerability Details CVE-2023-43013
Asset Management System v1.0 is vulnerable to an
unauthenticated SQL Injection vulnerability on the
'email' parameter of index.php page, allowing an
external attacker to dump all the contents of the
database contents and bypass the login control.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-43013
-
cpe:2.3:a:projectworlds:asset_management_system:1.0